Vulnérabilités
Vulnérabilités des apps suivies
25 946 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 25 946
- Activement exploitées
- 373
- Fenêtre de publication
- 1997-01-01 → 2026-09-29
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2019-25154
Inappropriate implementation in iframe in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted H… |
|
CVE-2024-6779
Out of bounds memory access in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML… |
|
CVE-2024-6778
Race in DevTools in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML i… |
|
CVE-2024-6777
Use after free in Navigation in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a malicious extension to potentially … |
|
CVE-2024-6776
Use after free in Audio in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr… |
|
CVE-2024-6775
Use after free in Media Stream in Google Chrome prior to 126.0.6478.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to pot… |
|
CVE-2024-6774
Use after free in Screen Capture in Google Chrome prior to 126.0.6478.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to p… |
|
CVE-2024-6773
Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML… |
|
CVE-2024-6772
Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to perform out of bounds memory access via a crafted HTML… |
|
CVE-2024-38020
Microsoft Outlook Spoofing Vulnerability |
|
CVE-2024-6615
Memory safety bugs present in Firefox 127 and Thunderbird 127. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2024-6614
The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 … |
|
CVE-2024-6613
The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 … |
|
CVE-2024-6612
CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked that a CS… |
|
CVE-2024-6611
A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128. |
|
CVE-2024-6610
Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen m… |
|
CVE-2024-6609
When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. This vulnerability affects Firefox < 128 and Thunderbird… |
|
CVE-2024-6608
It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulner… |
|
CVE-2024-6607
It was possible to prevent a user from exiting pointerlock when pressing escape and to overlay customValidity notifications from a `<select>` element ove… |
|
CVE-2024-6606
Clipboard code failed to check the index on an array access. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 128 and Thunder… |
|
CVE-2024-6604
Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume t… |
|
CVE-2024-6603
In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerabilit… |
|
CVE-2024-6602
A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird <… |
|
CVE-2024-6601
A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < … |
|
CVE-2024-6600
Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in private s… |
|
CVE-2024-39684
MEDIUM · éditeur
Github: CVE-2024-39684 TenCent RapidJSON Elevation of Privilege Vulnerability |
|
CVE-2024-38517
MEDIUM · éditeur
Github: CVE-2024-38517 TenCent RapidJSON Elevation of Privilege Vulnerability |
|
CVE-2024-38112
Windows MSHTML Platform Spoofing Vulnerability |
|
CVE-2024-38105
HIGH · éditeur
Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability |
|
CVE-2024-38104
HIGH · éditeur
Windows Fax Service Remote Code Execution Vulnerability |
|
CVE-2024-38102
HIGH · éditeur
Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability |
|
CVE-2024-38101
HIGH · éditeur
Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability |
|
CVE-2024-38100
HIGH · éditeur
Windows File Explorer Elevation of Privilege Vulnerability |
|
CVE-2024-38099
HIGH · éditeur
Windows Remote Desktop Licensing Service Denial of Service Vulnerability |
|
CVE-2024-38091
HIGH · éditeur
Microsoft WS-Discovery Denial of Service Vulnerability |
|
CVE-2024-38085
HIGH · éditeur
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2024-38080
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2024-38079
HIGH · éditeur
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2024-38078
HIGH · éditeur
Xbox Wireless Adapter Remote Code Execution Vulnerability |
|
CVE-2024-38077
CRITICAL · éditeur
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
|
CVE-2024-38076
CRITICAL · éditeur
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
|
CVE-2024-38074
CRITICAL · éditeur
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
|
CVE-2024-38073
HIGH · éditeur
Windows Remote Desktop Licensing Service Denial of Service Vulnerability |
|
CVE-2024-38072
HIGH · éditeur
Windows Remote Desktop Licensing Service Denial of Service Vulnerability |
|
CVE-2024-38071
HIGH · éditeur
Windows Remote Desktop Licensing Service Denial of Service Vulnerability |
|
CVE-2024-38070
HIGH · éditeur
Windows LockDown Policy (WLDP) Security Feature Bypass Vulnerability |
|
CVE-2024-38069
HIGH · éditeur
Windows Enroll Engine Security Feature Bypass Vulnerability |
|
CVE-2024-38068
HIGH · éditeur
Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability |
|
CVE-2024-38067
HIGH · éditeur
Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability |
|
CVE-2024-38066
HIGH · éditeur
Windows Win32k Elevation of Privilege Vulnerability |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.